This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Adventures with MSIE...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.securityfocus.com/archive/1/455965
Michal Zalewski - Jan 04 2007 10:22PM
"A while ago, apparently angry with Larry Seltzer, I penned a quick write-up on the possible issues with race conditions…Today, inspired by Brian Krebs' report* on MSIE's stellar track of security response that we all owe to responsible disclosure, I thought it would be a brilliant idea to test MSIE for the same class of problems (they had half a year to take notice of my original rant)…."
(…resulting in "Concurrency strikes MSIE (potentially exploitable msxml3 flaws)")
- http://www.securityfocus.com/archive/1/455967/30/0/threaded
Larry Seltzer - Jan 04 2007 10:36PM
"I hope you're still not angry!…"

Internet Explorer Unsafe for 284 Days in 2006
* http://blog.washingtonpost.com/securityfix…safe_for_2.html
January 4, 2007; 6:45 AM ET

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0099
Last revised: 1/8/2007
Impact
CVSS Severity: 2.7 (Low)
Range: Remotely exploitable
Authentication: Not required to exploit
Impact Type: Allows disruption of service
Vulnerable software and versions: MSIE 6, MSIE 7…
Vulnerability Type: Race Condition…

- http://isc.sans.org/diary.html?storyid=2004
Last Updated: 2007-01-09 02:29:36 UTC

:ph34r:
FYI…

- http://blog.washingtonpost.com/securityfix…ozilla_pat.html
January 19, 2007 ~ "A couple of weeks ago, Security Fix published some data* showing how risky it was for the average Windows user to browse the Web with Microsoft's Internet Explorer in 2006. That analysis found that for 284 days in 2006, bad guys were either exploiting critical, unpatched security holes in IE or blueprints for said instructions were published online for any criminals to use. In contrast, the data showed that there just nine days in 2006 in which exploit code was available for similarly serious, unpatched security holes in Mozilla's Firefox browser. A great number of people who commented on that story and sent e-mail about it have been asking to see the raw data that I used to compile that information. So, here it is:

Microsoft's 2006 Critical Patches
> http://blog.washingtonpost.com/securityfix/MS06.htm

Mozilla's 2006 Critical Patches
> http://blog.washingtonpost.com/securityfix/mozilla2006.htm

…Overall, I found that it took an average of about 113 days for Microsoft to issue critical updates in 2006. If you just look at all critical IE flaws that Microsoft patched in 2006 (not just the bolded ones, which indicate either the availability of pre-patch exploit code or evidence of active, pre-patch exploitation), Microsoft took about 90 days to push out an update. However, when it came to the most serious IE flaws (the ones in bold), Microsoft shipped a fix in about 40 days. This post wasn't meant to stir up the virtual hornet's nest that is the eternal IE vs. Firefox security and usability debate. I merely wanted to publish the data sets (which took a great deal of time to compile) because they could be useful for other researchers (plus, I already promised I'd publish them)…"

* http://blog.washingtonpost.com/securityfix…safe_for_2.html

.